HackTheBox: Codify

Enumeration 1 export target=10.129.47.211 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80,3000 -T5 $target -oN nmap_codify Add codify.htb to hosts: 1 echo "10.129.47.211 codify.htb" | sudo tee -a /etc/hosts Web Application (80) We can execute code, there are some limitations though: We learn that it uses vm2: Link redirects to github and the version is 3.9.16. Let’s search for a vulnerability if any exists. ...

August 11, 2026 · 3 min · 595 words · burkocyigit

HackTheBox: CozyHosting

Enumeration 1 export target=10.129.229.88 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add cozyhosting.htb to hosts 1 echo "10.129.229.88 cozyhosting.htb" | sudo tee -a /etc/hosts Web Application (80) Portfolio page There is a login page as well: Vhost fuzz 1 ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://cozyhosting.htb/ -H 'Host: FUZZ.cozyhosting.htb' --ac Nothing shows up. Directory Search 1 dirsearch -u http://cozyhosting.htb/ A lot of output, but the actuator is interesting: ...

August 11, 2026 · 2 min · 276 words · burkocyigit

HackTheBox: Active

Enumeration 1 export target=10.129.47.148 Port Scanning 1 2 3 rustscan $target --ulimit 10000 -g 10.129.47.148 -> [53,88,135,139,389,445,593,636,3268,3269,5722,464,9389,49153,49152,49155,49154,49158,49157,49162,49166,49168] 1 nmap -Pn -sC -sV -n -p53,88,135,139,389,445,464,3268,3269,5722,9389,47001,49152,49154,49153,49155,49158,49157,49162,49166,49168 -T5 $target Looking at the open ports (53, 88, …) this is clearly a Domain Controller. SMB Shares 1 smbmap -H $target We can read the non-default Replication share with null authentication. Let’s read it with smbclient: 1 smbclient -N //$target/Replication Get all files: ...

August 10, 2026 · 2 min · 254 words · burkocyigit

HackTheBox: Busqueda

Enumeration 1 export target=10.129.47.156 Port Scanning Add the domain to hosts: 1 sudo nano /etc/hosts Web Application (port 80) We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable. After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC. https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection Download the PoC: 1 git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git ...

August 10, 2026 · 2 min · 299 words · burkocyigit

SQL Injection Deep Dive: From Detection to Exploitation and Defense

Introduction SQL Injection (SQLi) remains one of the most critical web application vulnerabilities, consistently ranking in the OWASP Top 10. Despite being well-understood for over two decades, it continues to plague applications worldwide. In this article, we’ll deep-dive into SQLi — from how it works, to how attackers exploit it, and most importantly, how to defend against it. 💡 Key Takeaway: SQL injection occurs when user-supplied data is incorporated into SQL queries without proper sanitization, allowing attackers to manipulate database operations. ...

August 4, 2026 · 8 min · 1504 words · burkocyigit